首页> 外文会议>IEEE International Symposium on Cyberspace Safety and Security >A Decentralized Framework for Geolocation-based Pre-Incident Network Forensics
【24h】

A Decentralized Framework for Geolocation-based Pre-Incident Network Forensics

机译:基于地理位置的前事故网络取证的分散框架

获取原文

摘要

Throughout the last couple of years network forensics has gained higher importance due to the ever-growing quantity and quality of attacks. In contrast to conventional network forensics which relies on a central approach, both legal as well as technical guidelines nowadays favor a decentralized approach since aspects like privacy, limited data manipulation possibilities and scalability are addressed superiorly there. In this regard, however, present (decentralized) solutions are all in the need of an improvement especially in the area of protection against manipulation, i.e., falsification of relevant forensics data particularly in case of sophisticated attacks. Following the idea of strategic pre-incident preparation, this publication presents a decentralized approach, which, in advance, selectively collects data based on the suspiciousness of the connection to facilitate a (possible) investigation. To this end, we present an agent-based framework including prototype and evaluation that particularly uses Geolocation to fulfill this task.
机译:在过去几年中,由于攻击数量和攻击质量不断增长,网络取证已经提高了更高的重要性。与依赖于中央方法的传统网络取证相比,法律以及技术指南现在支持分散的方法,因为隐私等方面,有限的数据操纵可能性和可扩展性在那里得到解决。然而,在这方面,目前(分散的)解决方案尤其需要改进,特别是在防止操纵领域,即,特别是在复杂的攻击情况下伪造相关的取证数据。在战略预先入侵准备的思想之后,本出版物提出了一种分散的方法,提前选择性地基于联系的可疑地收集数据,以促进(可能)调查。为此,我们介绍了一个基于代理的框架,包括原型和评估,特别是使用地理位置来满足这项任务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号